From 68375c0420f5bc912b470c6e9177726b3f0ea37c Mon Sep 17 00:00:00 2001 From: Palma Solutions LTD Date: Thu, 15 Mar 2018 10:32:41 +0100 Subject: [PATCH] new pattern --- malware4.pl | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/malware4.pl b/malware4.pl index b83db15..668e39a 100644 --- a/malware4.pl +++ b/malware4.pl @@ -354,7 +354,12 @@ my @regexen = ( qr/<\?php\s+eval\(\"\?>\"\.base64\_decode\(\".+?\"\)\)\;\s+\?>/is, qr/<\?php\s+\$([A-z0-9]{1,20})\s+\=.+?\;\$([A-z0-9]{1,20})\s+\=\s+Array\(\)\;\$([A-z0-9]{1,20})\[\]\s+\=\s+\$([A-z0-9]{1,20})\[\d\]\.\$([A-z0-9]{1,20})\[\d\d\]\;\$([A-z0-9]{1,20})\[\].+?\;foreach\s+\(\$([A-z0-9]{1,20})\[\d\]\(\$\_COOKIE\,\s+\$\_POST\)\s+as\s+\$([A-z0-9]{1,20}).+?\$([A-z0-9]{1,20})\[\d\]\(\$([A-z0-9]{1,20})\)\)\)\)\;\}/is, qr/.+?\@HACKED\s+By\_BDJ\-007.+?var\s+pesen\=\"BDJ\-007\s+Was\s+Here\s+>\_\*\"\;.+?<\/script>\s+